Malicious PDF — malware analysis report

Static analysis result for SHA-256 4565ff143b9cc3ef…

MALICIOUS

PDF

21.2 KB Created: 2020-02-10 13:03:21 +00:00 Authoring application: mPDF 5.7
MD5: ccade95441afb196032e45b137ea5b82 SHA-1: 118ca3b0c21912fff828188bda76fd6374b5cace SHA-256: 4565ff143b9cc3ef9a7a90497b883c682f1277778f5784c96335a1887f739c0e
150 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1059.001 PowerShell

The PDF file contains a large number of embedded URLs, identified as a link farm. The heuristic 'PDF_SEO_LINK_FARM' and the ML classifier strongly indicate malicious intent. The embedded URLs, such as http://ieuicufioao.myhome.cx/2551558558558555/The-Vampire-Valkyrie-the-Dancing-Valkyrie-Book-2-by-Peter-Klein.pdf, are likely used to redirect users to malicious websites or phishing pages. No scripts were extracted from this sample.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9900

Heuristics 3

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • ClamAV: Pdf.Malware.Agent-9909948-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Malware.Agent-9909948-0
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://ieuicufioao.myhome.cx/2551558558558555/The-Vampire-Valkyrie-the-Dancing-Valkyrie-Book-2-by-Peter-Klein.pdf
    • http://ieuicufioao.myhome.cx/5559555553555/Valkyrie--The-vampire-princess-s-Clothes-Valkyrie--The-vampire-princess-0-by-Pet-Torres.pdf
    • http://ieuicufioao.myhome.cx/8553555559551/Valkyrie-The-Vampire-Princess-2-Valkyrie-the-vampire-princess-2-by-Pet-Torres.pdf
    • http://ieuicufioao.myhome.cx/7552553552553/Valkyrie-The-Vampire-Princess-4-Valkyrie---The-Vampire-Princess-4-by-Pet-Torres.pdf
    • http://ieuicufioao.myhome.cx/3559555551558551/The-Valkyrie-Mandate-The-Book-That-Changed-History-by-Robert-Vaughan.pdf
    • http://ieuicufioao.myhome.cx/3556557554553557/Valkyrie-The-Vampire-Princess-The-Vampire-Princess-1-by-Pet-Torres.pdf
    • http://ieuicufioao.myhome.cx/2553550559556555/Valkyrie-1-by-Bryan-J-L-Glass.pdf
    • http://ieuicufioao.myhome.cx/2558550559557553/Dead-Embers-Valkyrie-2-by-T-G-Ayer.pdf
    • http://ieuicufioao.myhome.cx/4555557558553557/Awakening-Valkyrie-Diaries-1-by-Kate-Young.pdf
    • http://ieuicufioao.myhome.cx/2552555553555551/Valkyrie-Vampyre-Productions-1-by-Mandy-M-Roth.pdf
    • http://ieuicufioao.myhome.cx/1551550559551553553/Valkyrie-s-Vengeance-Loki-s-Wolves-1-by-Melissa-Snark.pdf
    • http://ieuicufioao.myhome.cx/3557557556553553/Return-of-the-Asgard-The-Valkyrie-Chronicles-1-by-Erik-Schubach.pdf
    • http://ieuicufioao.myhome.cx/9559553555550559/Heart-amp-Shadow-The-Valkyrie-Duology-by-Amanda-Hocking.pdf
    • http://ieuicufioao.myhome.cx/8556553555559550/The-Golden-Valkyrie-The-Trustworthy-Redhead-Sedikhan-2-3-by-Iris-Johansen.pdf
    • http://ieuicufioao.myhome.cx/1551557558556555552/Valkyrie-North-American-s-Mach-3-Superbomber-by-Dennis-R-Jenkins.pdf
    • http://ieuicufioao.myhome.cx/4558557550555551/Disobeying-Hitler-German-Resistance-After-Operation-Valkyrie-by-Randall-Hansen.pdf
    • http://ieuicufioao.myhome.cx/1550553550555550556/The-Hitler-Conspirator-The-Story-of-Kurt-Freiherr-Von-Plettenberg-and-Stauffenberg-s-Valkyrie-Plot-to-Kill-the-Fuhrer-by-Eberhard-Schmidt.pdf
    • http://ieuicufioao.myhome.cx/6559551550553555/Cygne-Dans-La-Culture-Cygne-Le-Lac-Des-Cygnes-Lohengrin-Parsifal-Leda-Et-Le-Cygne-Hyoga-Valkyrie-Le-Cygne-Et-La-Princesse-Le-Vilain-Petit-Canard-Les-Cygnes-Sauvages-an-Alarc-h-Volund-Femme-Cygne-Barbie-Et-Le-Lac-Des-Cygnes-by-Source-Wikipedia.pdf
    • http://ieuicufioao.myhome.cx/4559554558550555/Kiera-Hudson-Limited-Edition-Series-One-Vampire-Shift-Vampire-Wake-amp-Vampire-Hunt-Book-1-by-Tim-O-39-Rourke.pdf
    • http://ieuicufioao.myhome.cx/3550551556550552/Mudpoo-and-the-Fungus-Mystery-by-Peter-Klein.pdf
    • http://ieuicufioao.myhome.cx/2552555553555551/Valkyrie-Vampyre-Productions-